CVE-2020-1736: Fedoraproject Fedora

Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less restrictive permissions before the move. This could lead to the disclosure of sensitive data. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

Affected products

  • Fedoraproject Fedora: version 31 only; version 32 only
  • Red Hat Ansible: up to and including 2.7.16; from 2.8.0, before 2.8.15 (fixed in 2.8.15); from 2.9.0, before 2.9.13 (fixed in 2.9.13)
  • Red Hat Ansible Tower: up to and including 3.3.4; from 3.3.5, up to and including 3.4.5; from 3.5.0, up to and including 3.5.5; from 3.6.0, up to and including 3.6.3; from 3.7.0, up to and including 3.7.2
  • Red Hat Cloudforms Management Engine: version 5.0 only
  • Red Hat Openstack: version 13 only

Published 2020-03-16. Last modified 2026-06-17.